Terms of Service
These Terms of Service (“Terms“) govern your access to and use of pentesterspace.com (the “Website“) and the cybersecurity services (the “Services“) provided by Pentester Space Ltd. (“Pentester Space,” “we,” “us,” or “our“).
Pentester Space Ltd. is a company registered in Bangladesh under registration number C-213253/2026, with its registered office at 15/A/10 New, West Rajabazar, Panthapath, Sher-e-Bangla Nagar, Dhaka 1215, Bangladesh.
By accessing the Website or using the Services, you agree to these Terms. If you use the Website or Services on behalf of a company or other organization, you confirm that you have authority to bind that organization to these Terms, and “you” refers to that organization.
The Services are offered to businesses, organizations, and professionals rather than to individual consumers.
Your use of the Website is also governed by our Privacy Policy.
1. Our Services
Pentester Space provides cybersecurity services that may include:
- Penetration testing
- Vulnerability assessment
- Security assessments
- Application and API security testing
- Infrastructure security testing
- Security consulting
- Other cybersecurity-related services
Specific services, scope, deliverables, timelines, and fees are defined in a separate proposal, statement of work, or service agreement (each an “Engagement Agreement“).
2. Order of Precedence
If there is a conflict between these Terms and a signed Engagement Agreement, non-disclosure agreement, or data processing agreement, the signed agreement prevails to the extent of the conflict. These Terms continue to apply to everything the signed agreement does not address.
3. Authorization for Security Testing
All security testing performed by Pentester Space must be authorized by the owner of the relevant systems or assets, or by a person with legal authority to act on the owner’s behalf.
Testing will not begin until we have received written authorization, such as a signed authorization form, rules of engagement, or Engagement Agreement, that identifies the assets to be tested and confirms that the signatory has authority to authorize the testing.
You represent and warrant that:
- You own the systems, applications, domains, networks, or infrastructure submitted for testing, or have the legal authority to authorize testing of them.
- Where an in-scope asset is hosted, operated, or managed by a third party, including cloud and hosting providers, you have confirmed that the third party permits the testing and have given any notice the third party requires.
- The scope and authorization information you provide is accurate and complete.
You must not request or instruct Pentester Space to test systems for which you do not have appropriate authorization.
4. Scope of Testing
Testing will be performed only against assets included within the agreed scope. Pentester Space will not test outside the agreed scope without prior written authorization.
You are responsible for providing accurate scope information, including identifying systems that must not be tested, any testing windows or restrictions, and emergency contacts. Changes to scope after an engagement has started must be agreed in writing before they take effect.
5. Nature and Risks of Security Testing
Security testing simulates the techniques used by real attackers. Even when performed carefully and within scope, testing may cause system instability, performance degradation, service interruption, security alerts, increased log volume, data modification, or, in rare cases, data loss.
You acknowledge these inherent risks and agree that Pentester Space is not liable for such effects arising from in-scope testing performed with reasonable professional care. You are responsible for maintaining backups and business continuity measures before testing begins.
Where an engagement includes exploitation of vulnerabilities, we will use reasonable efforts to avoid unnecessary disruption and will follow any restrictions set out in the Engagement Agreement.
6. Customer Responsibilities
You are responsible for:
- Providing accurate information necessary to perform the Services.
- Providing appropriate written authorization for testing.
- Maintaining backups and appropriate business continuity measures.
- Informing, and obtaining any required permissions from, relevant third parties, including hosting and cloud providers.
- Providing access credentials or test accounts where necessary.
- Promptly notifying Pentester Space of any relevant changes to the testing environment.
- Complying with all laws that apply to you in connection with the Services.
- Deciding whether and how to remediate reported findings.
Pentester Space is not responsible for issues caused by inaccurate information, unauthorized changes, systems outside the agreed scope, or your failure to remediate reported findings.
7. Security Findings and Reports
Security assessments may identify vulnerabilities, weaknesses, or security risks. We will communicate findings according to the agreed deliverables and reporting process.
Findings reflect the state of the tested systems at the time of testing. Changes made after testing, vulnerabilities disclosed later, and threats that emerge later fall outside the assessment.
A security assessment does not guarantee that every vulnerability or security issue will be identified, and does not guarantee that the tested systems are or will remain secure.
8. Handling of Data Accessed During Testing
During testing we may gain access to data held in your systems, including personal data, credentials, and confidential business information. We will:
- Access such data only to the extent necessary to perform the Services and demonstrate findings.
- Not copy, extract, or retain such data beyond what is reasonably needed as proof of concept for reported findings.
- Store engagement data, including credentials, evidence, and screenshots, securely for the duration of the engagement.
- Securely delete engagement data in line with the retention schedule published in our Privacy Policy. In particular, credentials, API keys, and tokens are destroyed as soon as they are no longer required and never held for more than 90 days; proof-of-concept evidence and raw scan results are held for 6–12 months. Retention differs only where it is agreed in writing or required by law.
Where the data we access includes personal data, you remain the controller of that data and we act as a processor on your instructions. A data processing agreement is available on request. Our handling of personal data is described further in our Privacy Policy.
9. Confidentiality
Each party will treat the other party’s confidential information as confidential, use it only for the purposes of the engagement, and use reasonable measures to prevent unauthorized disclosure. Our confidential information includes our methodologies, tools, and pricing. Your confidential information includes scope details, findings, reports, and information about your systems.
These obligations do not apply to information that is or becomes publicly available without breach of these Terms, was already lawfully known to the receiving party, was independently developed, or must be disclosed by law, regulation, or court order. In the last case the receiving party will, where lawful, give the other party prompt notice.
If during an engagement we discover a previously unknown vulnerability in third-party software or hardware, we may report it to the affected vendor through a responsible disclosure process without revealing your identity or confidential information, unless the Engagement Agreement provides otherwise.
Additional confidentiality obligations may be established through a separate NDA or Engagement Agreement.
10. Prohibited Use
You must not use the Website or the Services to:
- Request unauthorized access to systems.
- Conduct illegal activities.
- Attack systems without appropriate authorization.
- Submit malicious content intended to harm our infrastructure.
- Circumvent security controls for unlawful purposes.
- Misrepresent your authority to test a system.
- Interfere with the operation of the Website or access it by any means other than the interface we provide.
We may suspend or terminate access where we reasonably believe the Website or Services are being misused.
11. Intellectual Property
Unless otherwise agreed in writing, Pentester Space retains ownership of the Website, its content, and our software, methodologies, tools, templates, and other pre-existing intellectual property.
Customer-specific reports and deliverables are handled according to the applicable Engagement Agreement. Unless that agreement says otherwise, you may use reports and deliverables for your internal security purposes and share them with your auditors, regulators, and professional advisers under confidentiality obligations. You may not publish our reports, or use our name or logo publicly, without our written consent.
12. Subcontractors
Pentester Space may engage vetted associate testers or subcontractors to perform parts of the Services. We remain responsible for their work and for ensuring they are bound by confidentiality and data protection obligations no less protective than these Terms.
13. Fees and Payments
Fees, payment schedules, cancellation terms, and other commercial conditions are specified in the applicable proposal, invoice, statement of work, or Engagement Agreement.
Unless otherwise stated, fees are exclusive of applicable taxes, and invoices are payable within 30 days of the invoice date. We may suspend work on overdue accounts after giving notice.
14. Third-Party Services
The Website may contain links to third-party websites or services. We do not control and are not responsible for third-party services, content, availability, or policies.
15. Disclaimer
The Services are provided based on the agreed scope and available information. While we use reasonable professional practices, we do not guarantee that the Services will identify every vulnerability, security weakness, threat, or future security incident.
The Website and its content are provided “as is” and for general information only. Nothing on the Website constitutes security, legal, or other professional advice for your specific situation. To the maximum extent permitted by applicable law, we disclaim all warranties, express or implied, in relation to the Website.
16. Limitation of Liability
To the maximum extent permitted by applicable law:
- Pentester Space will not be liable for indirect, incidental, special, consequential, or punitive damages, or for loss of profits, revenue, data, or business, arising from the use of the Website or Services.
- Pentester Space will not be liable for losses caused by your failure to remediate reported findings, by attacks or actions of third parties, by changes to systems outside the agreed scope, or by inaccurate information you provide.
- Pentester Space’s total liability arising out of or in connection with the Services will not exceed the fees you paid under the relevant Engagement Agreement in the twelve (12) months before the event giving rise to the claim.
Nothing in these Terms excludes or limits liability that cannot be excluded or limited under applicable law.
Additional limitations of liability, warranties, or indemnification obligations may be established in a separate written agreement.
17. Indemnification
You agree to indemnify and hold harmless Pentester Space and its personnel against all claims, losses, damages, liabilities, and expenses, including reasonable legal fees, arising from:
- Testing performed in reliance on authorization or scope information you provided that was inaccurate, incomplete, or that you were not entitled to give.
- Your breach of these Terms or of applicable law.
- Claims by third parties, including hosting providers and users of your systems, relating to authorized testing performed within the agreed scope.
18. Suspension or Termination
We may suspend or terminate access to the Website or Services if you violate these Terms, misuse the Services, or engage in unlawful or unauthorized activities.
Termination of an engagement is governed by the applicable Engagement Agreement. On termination for any reason, fees for work performed up to the date of termination remain payable, and each party will return or securely destroy the other party’s confidential information on request, subject to Section 8 and any legal retention requirements.
Sections 8, 9, 11, 13, 15, 16, 17, and 21 survive termination.
19. Force Majeure
Neither party is liable for delay or failure to perform caused by events beyond its reasonable control, including natural disasters, internet or utility failures, government actions, or labor disputes, provided it uses reasonable efforts to resume performance. Payment obligations are not excused.
20. General
- Entire agreement. These Terms, together with any signed Engagement Agreement, NDA, or data processing agreement, form the entire agreement between us regarding the Services.
- Severability. If any provision is found unenforceable, the remaining provisions remain in effect.
- Waiver. A failure to enforce any provision is not a waiver of it.
- Assignment. You may not assign these Terms without our written consent. We may assign them to an affiliate or a successor to our business.
- Independent contractors. The parties are independent contractors. Nothing in these Terms creates a partnership, joint venture, agency, or employment relationship.
- Notices. Notices to us must be sent to the contact details in Section 23.
21. Governing Law and Disputes
These Terms are governed by the laws of Bangladesh, without regard to conflict-of-law principles. Any dispute arising out of or in connection with these Terms or the Services is subject to the exclusive jurisdiction of the courts of Dhaka, Bangladesh.
Before starting formal proceedings, the parties will attempt in good faith to resolve the dispute through discussion between senior representatives for at least 30 days.
22. Changes to These Terms
We may update these Terms from time to time. Updated Terms will be published on this page with a revised effective date. By using the Website or Services after an updated version becomes effective, you agree to the revised Terms. Changes do not affect engagements governed by a signed Engagement Agreement entered into before the change.
23. Contact
Pentester Space Ltd.
15/A/10 New, West Rajabazar, Panthapath
Sher-e-Bangla Nagar, Dhaka 1215, Bangladesh
Website: pentesterspace.com
General and legal inquiries: contact@pentesterspace.com
Privacy-related matters: privacy@pentesterspace.com